Hi, this is Tom Field, senior vice president of editorial with information security media group. I want to welcome you back to my series of 2020 visions interviews with thought leaders about the security outlook in the coming year. My pleasure to be speaking today with Tom Kellerman, he's the head of cybersecurity strategy with VMware. Tom, thank you so much for taking time to speak with me.
Thank you. It's always a pleasure, Tom. I always love asking you this question at the end of the year, and I always know it's a loaded question. So, as we enter 2020, what are the threats and the threat actors that concern you the most?
Well, the threat actors specifically are the usual suspects on the axis of evil in cyberspace. As you see, more robust and organized cyber activity occurring from both China and Russia and from their allies, North Korea and Iran, both of which have exemplified true cyber attack capabilities in the organization over the past year, thanks to tech transfer and consultative services being provided by their big brothers. This is not just a question of disinformation, this is not a question of political affiliation. This is along the strategy and along the lines of information dominance being the primary strategy to reassert the hegemonic roles of those empires.
So, I'm very concerned with the use of road nation states in attacking the West as proxies for their allies. Tom, you've been sounding this alarm for several years now. So, I want to ask you to take a step back and talk to him about where have we made progress in cyber defense, and where do you feel we still lag significantly behind? Well, we're lagging behind because we don't appreciate the evolution of the cognitive attack loop of the adversary.
What I mean by that is the cognitive attack loop is a carbon black manifestation as an evolution of the kill chain. The kill chain for too long has been too linear, it makes the assumption that the adversaries will get in and get out with what they want, and then they will leave, given the dramatic uptake of island hopping, 41% of the time, that it's occurring in investigations, where they're actually taking over and common during the infrastructure of the victim companies so that they can use that brand to target their constituency, coupled with counter incident response, and dramatic evolution and lateral movement beyond PowerShell. We have to appreciate that the adversary isn't leaving, they're never going to leave. Once they have your infrastructure, they will maintain a footprint on your infrastructure and they will maintain persistence.
And so, how we react to them, how we defend against them must be along the lines of a focus mission towards intrusion suppression, not just prevention. And we need to come to do this on that and have that awakening that we need to deal with an adversary that's already inside of our environment, and we need to suppress them in a clandestine fashion so they don't leverage destructive attacks. So, on for as many years as you and I've been talking, you've been talking about island hopping. So, I want to ask you to go into that with some depth.
What forms of island hopping are taking place now, and why can't we as defenders get a handle on this? Well, first and foremost, as defenders, let's realize that, yes, they will target you through your information supply chain, which includes your outside general counsel, which includes your outside marketing firm, which includes your cloud service provider, but they're not going to stop with you. Anyone that's going to use your information supply chain to attack you will then use you to attack those who depend on your services and your capabilities as well. And so, number one, we need to have a recognition and appreciation for the fact that island hopping as a modus operandi will not stop, and it will continue from the point of presence when they come into your infrastructure.
Okay? Secondarily, island hopping is not limited to network-based island hopping, a tax-wide network. They also include, obviously, water and oil attacks, which manifest not just vis-a-vis the websites of major corporations, but manifest through their mobile applications as well as these mobile apps are still vulnerable to the OAuths top 10, you and I both know this. This is compounded by the fact that there's a new form of island hopping out there called reverse business e-mail compromise, do not confuse this with business e-mail compromise.
This is when they commandeer your mail server, and because it's inside your perimeter and because it's got encryption and because it's e-mark enabled, you assume that it's safe, there's no spam coming off of it, so everything's good, but realistically, as they commandeer your mail server, they use machine learning to identify who the most important people are that communicate with this mail server. They use machine learning to discern what are the most likely three sentences that were used in previous conversations, and then they push Filet's malware against your board of directors and your largest customer set, specifically the C-level at those customers. And this is a very elegant, yet sophisticated attack campaign that has been growing in its ubiquity, not just in the Russian underground, Eastern Europe, but in Brazil and in Southeast Asia over the past six months. And we need to take close attention to the fact that many adversaries in today's world will use our islands to hop, and they won't stop with us.
Tom, what if you might talk to me a little bit about process hollowing? What it is and how hackers are using it now? Well, essentially, they're using a legitimate process to embed a secondary process that allows them to compromise trusted communications within an organization. They have a way of, because of the limitations of visibility that most of us as defenders have, what is occurring within processes and when processes initialize a new process that is not legitimate, they misuse that trusted ecosystem many times, it's Microsoft tools and capabilities and protocols, but not limited to that.
For example, many of us think that PowerShell is the number one problem for lateral movement, but in fact, it's actually WMI in today's world. And this is compounded by the fact that they're still implementing old forms of flycraft within our infrastructure as to leverage secondary commending controls like secondography, etc. But we need to increase visibility. The number one thing we must do is we must integrate our security controls.
We must have intrinsic cybersecurity through integration of all of our security controls. We need to do a better job of doing things like micro-segmentation, but most importantly, we have to be able to capture unfiltered data on all of our endpoints for at least 30 days to ascertain root cause, because the likelihood of you actually stopping the attacker and the initial breach is minimal because of the nature in which not only are there forms dedicated to the customization of malware, but because wireless attacks and island hopping is occurring so widely. Tom, I wanted to talk to me a little bit about destructive attacks and why you see those not only increasing but escalating. Yeah, this is keeping me up at night and granted I've been in cybersecurity for 22 years now and I'm saddened to say that it hasn't gotten any better in fact, it's gotten dramatically worse and it's compounded by the convergence that we're seeing between the physical and digital world.
Now to that point, destructive attacks have increased yet again and they're occurring roughly 40% of the time based on our partners' evaluations and investigations. I think there are two reasons for this. It really depends on who you are as an organization, but geopolitical tension is manifesting in cyberspace and many times geopolitical tension serves as a harbinger for destructive attacks, but not limited to. More importantly, I think it's because we've been conducting into the response too loudly for too long.
Seeing this transition from burglary to home invasion and now to arson as a result of the fact that the defender is too loud about how they react to the adversary. In many cases, it's best that you not turn on the lights and cry out, I've got a gun and I've called the cops metaphorically when conducting incident response because they may choose to drop a wiper inside your infrastructure or leverage ransomware and not pet you style against you without demanding ransom. But it's not limited to that. Destructive attacks can expand to more tactical endeavors of destruction like deletion of logs, manipulation of time, segregation of subnets, et cetera, et cetera.
And this is becoming mainstream. Pretty much like a mafia I used to recommend to their captain to burn the evidence back in the day. This is the same phenomenon that we're seeing in cyber. And primarily, I think that for the audience and your sophisticated audience should recognize that we, as a collective, as a community, must have the serious conversation of how can we improve incident response to make it more clandestine because currently, even though we do a fairly good job of incident response, we are doing it too loudly.
Tom, a few minutes ago, I used the term home invasion. Do you suspect in this broader threat landscape that targeted virtual home invasions were going to become common? I do. And we can chuckle at cyber security experts when we see the news about the ring breaches and the attacks on ring systems and homes.
And you have these miscreants that are just being morons, traumatizing families in that fashion. But because of the connected world and because of the nature in which the leadership of your organization, because they're wealthy, will have a very highly connected home filled with smart speakers and smart cameras and smart lights and smart heating and cooling systems. We need to appreciate the fact that it's an inevitable migration to extortion from ransom or to virtual home invasions. And I do think that that will become more mainstream in this coming year in a targeted fashion.
The sea levels of major corporations as well as politicians before ideological purposes. Dometically in the U.S., I'm very concerned with the dramatic uptick of cyber capabilities and desire to become cyber capable of DT domestic terror groups across the U.S., many of which who are beginning to do more than going to the gun range with their friends, but who are beginning to arm up with a myriad of attack capabilities and leveraging them in interesting ways. One of the big themes for 2020 is going to be the broadening of the attack surface through the widespread deployment of 5G. What are your security concerns about 5G development, Tom?
Oh boy, well, it is not mythology. One of the more proactive stances that the U.S. government has taken in recent years vis-a-vis supply chain issues of vulnerabilities has been their reticence to employ foreign 5G capabilities across critical infrastructure. But really, as an individual or as a corporation, you need to wrap your head around the following.
5G, given that it has supply chain issues, even though it does a better job of helping you protect traditional mobile transactions, it doesn't have the gateway vulnerability or some of the other outstanding vulnerabilities associated with previous protocols, 5G because of the nature in which IOT and OT, especially OT, are relying upon it to facilitate their communications and obviously to manipulate and create wide-area networks, we need to appreciate that anyone that can control 5G or hack 5G can now control your physical reality through your OT and IOT. And that is a big implication. It is not just a question of your emails being monitored, it is not just a question of your intellectual property being stolen, it is a true question of whether or not an adversary can literally teleport themselves into your physical environment through 5G because of the ubiquitous use of OT and IOT and then become relatively physically present in that environment. Do you take any comfort at all from the efforts by global manufacturers to come up with 5G standards?
Awesome, but you have to remember who is sitting on those standards, and frankly, I think the 5G and the nature in which 5G poses a systemic risk to the security and privacy of the Western world, I think this is a great opportunity for the Nordics to realize the technological boom. And I'm not going to name how many is here, but it's obvious that there are two companies in the Nordics that would greatly benefit from the very proactive cybersecurity stance that they have taken over the years and they just need to do a better job of marketing into the world. Tom, just over a decade ago, you had the privilege to be on the panel that helped to inform the cybersecurity knowledge and policy of the Obama administration. We're going into another presidential election in 2020.
What are the cybersecurity issues that you want to see discussed at a federal level for whomever our new president is? You know, let's speak to the commission on cybersecurity briefly. We provided some great strategic opportunities for public policy and cyber space to the administration, and they only realized and acted upon approximately 40% of them. They were hamstrung by two ideological constructs that did not apply to the current cyber space.
Number one, the worst case scenario for them was the digital moral harbor that Dick Clark keeps speaking of, which frankly is mythology because we're dealing with a cyber insurgency in the US, not a Pearl Harbor-like scenario. And because of the multiplicity of actors and the use of cyber criminals as proxy explanations states, and the fact that we're dealing with that one hopping all the rest of it, that threat picture, threat analysis was not effective in using it as a marker or a benchmark. Number two, there was too much influence from K Street and laissez-faire economics dominating on the fact that we shouldn't impose any sort of a proactive regulation in the space, which has led us to the point we are today, which is problematic to me because, you know, the market is failed. And frankly, not only does the market is failed, the market has solved the problem, like everyone said it would, it's created the dark web economy of scale.
But I'll leave that there. Now, in terms of the elections, it's not just the US, but the French and the British who have suffered significant malign influence operations, I'm quoting the director of the FBI in this regard. The French have done a better job than the US and the British in containing and marginalizing those attacks. But we need to appreciate whether you're a public or a Democrat that, for example, China and Iran also have a dog on the site.
They don't have the same goal as Russia, and they are acting out in cyber spaces that relate to these malign influence operations, and that was stated by the director of the FBI and testimony to Congress a month ago. This is compounded with the fact that we continue to think of a problem as a voter role, a vote manipulation, and that's not actually the most significant challenge we face. The number one challenge we face is the fact that the voter databases can and will be hacked and have been hacked in many cases, depending on the state, and the voter roles themselves can be changed. The integrity of your name, your address, your birthday can be changed so that when you show up to vote, you're not allowed to vote, and you are suppressed, and you are disenfranchised, and you can do this specific to a political party.
Then finally, you have the nature of which states themselves actually post on an hourly basis through a website from the Secretary of State, updates on who's winning in the race, and if you were to manipulate the results on that website, and you and I both know that these issues should do, you could actually get forced to be disillusioned and disaffected Americans who really didn't want to vote to begin with who were just coming home from work to say, oh, forget it, forget it, he or she's already winning, it's a landslide, my vote won't count. And thus, you know, you can lean one state in one direction or another that way as well. So we need to look at this holistically, in fact, CISA, or DHS, has put out some fantastic recommendations on how to secure these systems and how to deal with these types of scenarios, but those recommendations are taken to relieve it, they're not mandated, and at a minimum, the states should be taking advantage of the offer from CISA to conduct threat hunting within those electoral systems to get rid of the attack ass or the back doors that have already been put in there by our adversaries. But this is not just a question of Russia, this is a question of numerous nation states having a dog in the fight and realizing that it is possible to affect the future of the United States and undermine democracy as a whole.
Tom, my head is spinning from the topics we've covered in this conversation. I've got to ask you, given everything that we face and the role that you're in today, are there technologies that particularly encourage you as we go into the new year that can help us to significantly bolster our cyber defenses? Yes, there are. Yes, there are.
We really need to be able to weave all of our security controls into our infrastructure, which can no longer have separate security strategies across infrastructure and across endpoints. In addition to that, I think the nature in which the evolution of end-point protection platforms is now focusing on behaviors and behavioral anomalies is greatly beneficial to the world that we live in. Because of the nature, we've got to stop focusing on the munitions and the payloads used by the adversary. It's more important to focus on how did that person take the shot in the first place, how did they know you would be in standing there, and more importantly, where they alone.
That's the world we live in today, not focusing on the bullet or the malware any longer. I would also stress that, as application control evolves, it's no longer your grandma's white listening. There's many unique things that can be done to ensure that systems only operate the way they were intended. I think Juffin Time Administration is here to stay, and it's a very important historic moment in our world that we realize that administrators shouldn't have perpetual administrative rights, and you should have the capacity to change administrative access specific to risk or threat to the infrastructure.
And then dynamic micro-segmentation is awesome. Imagine if you could micro-segment or inhibit lateral movement or move the doors and the walls within your infrastructure in real time specific to threat and root cause. That's a great injustice to suppressing intruders of tomorrow. Tom has always appreciated your time and insight, and I enjoy speaking with you.
Thank you so much for sharing your thoughts as we head into the new year. Thank you, Tom. Appreciate you. Happy New Year.
Again, I'm speaking with Tom Gellerman. He is the Head Cybersecurity Strategist with VMware. For Information Security Media Group, I'm Tom Field. Thank you very much.